Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2445 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.54% | — | Backstage Backend-plugin-apiAIBackstage Cli-commonAI | 21/1/2026 | 17/6/2026 | Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent… | |
| Aplazada | Alta (7.1) | 0.53% | — | Backstage Backend-defaultsAIBackstage Plugin-scaffolder-backendAIBackstage Plugin-scaffolder-nodeAI | 21/1/2026 | 15/7/2026 | Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log`… | |
| Aplazada | Alta (8.6) | 0.75% | — | Nodebb Plugin EmojiAI | 21/1/2026 | 17/6/2026 | NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file… | |
| Analizada | Crítica (10) | 73% | ⚠ Explotación activa💥 PoC | Oracle Http ServerOracle Weblogic Server Proxy Plug-in | 20/1/2026 | 25/8/2026 | Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable… | |
| Aplazada | Alta (7.5) | 0.43% | — | Kraftplugins Demo Importer PlusAI | 17/1/2026 | 17/6/2026 | The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vulnerable… | |
| Aplazada | Media (5.8) | 0.23% | — | Fullworksplugins Quick Contact FormAI | 17/1/2026 | 17/6/2026 | The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6. This is due to the 'qcf_validate_form' AJAX endpoint allowing a user controlled parameter to set the 'from' email address. This makes it possible for unauthenticated attackers to send emails to… | |
| Aplazada | Media (6.4) | 0.26% | — | Plugin-planet User Submitted PostsAI | 16/1/2026 | 17/6/2026 | The User Submitted Posts – Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'usp_access' shortcode in all versions up to, and including, 20260110 due to insufficient input sanitization and output escaping on user supplied attributes.… | |
| Aplazada | Media (5.3) | 0.26% | — | Payhere Payment Gateway Plugin FOR WoocommerceAI | 14/1/2026 | 17/6/2026 | The PayHere Payment Gateway Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to an improper validation logic in the check_payhere_response function in all versions up to, and including, 2.3.9. This makes it possible for unauthenticated attackers to change the status of… | |
| Aplazada | Alta (7.1) | 0.26% | — | E-plugins Real Estate PROAI | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Real Estate Pro real-estate-pro allows Reflected XSS.This issue affects Real Estate Pro: from n/a through <= 2.1.4. | |
| Aplazada | Alta (7.1) | 0.21% | — | E-plugins ListinghubAI | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins ListingHub listinghub allows Reflected XSS.This issue affects ListingHub: from n/a through 1.2.6. | |
| Aplazada | Media (6.1) | 0.14% | — | SVG MAP PluginAI | 7/1/2026 | 17/6/2026 | The SVG Map Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0. This is due to missing or incorrect nonce validation on multiple AJAX actions including 'save_data', 'delete_data', and 'add_popup'. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.4) | 0.28% | — | Sigmaplugin Advanced Database Cleaner PROAI | 7/1/2026 | 7/10/2026 | Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue affects Advanced Database Cleaner PRO: from n/a through 3.2.10. | |
| Aplazada | Media (4.3) | 0.18% | — | BBR Plugins Better Business ReviewsAI | 6/1/2026 | 7/10/2026 | Missing Authorization vulnerability in BBR Plugins Better Business Reviews better-business-reviews allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Business Reviews: from n/a through <= 0.1.1. | |
| Aplazada | Alta (7.1) | 0.22% | — | E-plugins JobbankAI | 6/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins JobBank jobbank allows Reflected XSS.This issue affects JobBank: from n/a through <= 1.2.2. | |
| Aplazada | Alta (8.6) | 1.7% | 💥 Exploit | Team Wordpress PluginAI | 5/1/2026 | 17/6/2026 | The Team WordPress plugin before 5.0.11 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | |
| Aplazada | Alta (7.1) | 0.18% | — | Nebelhorn Blappsta Mobile APP PluginAI | 31/12/2025 | 23/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App:… | |
| Aplazada | Media (5.3) | 0.21% | — | Gsplugins GS Portfolio FOR EnvatoAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in GS Plugins GS Portfolio for Envato gs-envato-portfolio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GS Portfolio for Envato: from n/a through <= 1.4.2. | |
| Aplazada | Media (4.3) | 0.22% | — | Themeboy Hide PluginsAI | 31/12/2025 | 23/9/2026 | Missing Authorization vulnerability in ThemeBoy Hide Plugins hide-plugins allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hide Plugins: from n/a through <= 1.0.4. | |
| Aplazada | Media (6.5) | 0.16% | — | Postieplugin PostieAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wayne Allen Postie postie allows Stored XSS.This issue affects Postie: from n/a through <= 1.9.73. | |
| Aplazada | Media (6.5) | 0.17% | — | Basepress Knowledge Base Documentation & Wiki PluginAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BasePress Knowledge Base documentation & wiki plugin – BasePress basepress allows Stored XSS.This issue affects Knowledge Base documentation & wiki plugin – BasePress: from n/a through <= 2.17.0.1. | |
| Aplazada | Media (4.3) | 0.18% | — | Kraftplugins Demo Importer PlusAI | 30/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Kraft Plugins Demo Importer Plus demo-importer-plus allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Demo Importer Plus: from n/a through <= 2.0.8. | |
| Aplazada | Alta (7.1) | 0.22% | — | Plugin OptimizerAI | 29/12/2025 | 7/10/2026 | Missing Authorization vulnerability in pluginoptimizer Plugin Optimizer plugin-optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Plugin Optimizer: from n/a through <= 1.3.7. | |
| Aplazada | Alta (8.6) | 0.28% | — | Plugin OrganizerAI | 29/12/2025 | 7/10/2026 | The Plugin Organizer WordPress plugin before 10.2.4 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers to perform SQL injection attacks. | |
| Aplazada | Alta (7.5) | 0.24% | — | Userproplugin UserproAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in DeluxeThemes Userpro userpro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Userpro: from n/a through <= 5.1.9. | |
| Aplazada | Media (6.5) | 0.16% | — | Pickplugins Post GridAI | 24/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Post Grid and Gutenberg Blocks post-grid allows Stored XSS.This issue affects Post Grid and Gutenberg Blocks: from n/a through <= 2.3.23. |